ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)
2026-07-25T01:23:45Z•abc96f0226a9e4342f04e4d734874d28f3f36eecc093430d7c9e3d9a423fbf81
CVE-2026-63030ai-securityautonomous-attackercaptive-portalexploitationgeoserverhikvisionhoneypotsiot-camerasremote-code-executionrondoscanningsql-injectionthreat-intelwordpresswp2shell
What happened
SANS ISC diary posts (19–24 Jul 2026) cover multiple active observations: active exploitation of a newly-assigned WordPress Core SQL injection (wp2shell) tracked as CVE-2026-63030 that can lead to unauthenticated remote code execution; internet-wide scans targeting Hikvision devices and the Hikvision Intelligent Security API; observed activity involving Rondo and GeoServer in honepot logs; examples of non-malicious but odd traffic (captive-portal detection); and commentary on risks when an "autonomous attacker" is an organization’s own AI model. Several daily Stormcast podcast entries are also
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- abc96f0226a9e4342f04e4d734874d28f3f36eecc093430d7c9e3d9a423fbf81
- Enrichment time
- 2026-07-25T01:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.